- update, files and the 6 /api catalog controllers now live in the engine on a new WarpEngine::ApiController base (same rescue/mime behavior as host) - engine routes serve /update, /file/*path, /api/software*, /api/builds*, /api/image/:id, /api/download at unchanged public paths via the root mount; host routes keep only TTG endpoints (events, members, wiki, rss, swagger) - /update secret comes from WarpEngine.config.update_secret and an unconfigured secret now rejects every request (previously an empty UPDATE_SECRET env accepted empty secrets) - apipie-rails is an engine dependency (DSL in engine controllers); dummy app configures apipie with validation off, mirroring the host - engine request specs: catalog controller specs moved from host plus new /update auth contract spec Verified: engine suite 53 green, host suite 6 green, /api/software and /api/builds byte-identical to baselines, /update 401/400 behavior intact, admin and TTG endpoints OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
14 lines
500 B
Ruby
14 lines
500 B
Ruby
WarpEngine::Engine.routes.draw do
|
|
namespace :api do
|
|
get "software", to: "software#index"
|
|
get "software/highlighted", to: "software_highlighted#index"
|
|
get "image/:id", to: "images#show"
|
|
get "download", to: "downloads#show"
|
|
get "builds", to: "builds#index"
|
|
get "softwares/:name/builds", to: "software_builds#show"
|
|
end
|
|
|
|
get "update", to: "update#update"
|
|
get "file/*path", to: "files#show", format: false
|
|
end
|